CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-29620

    Last Modified: 21 Nov 2024

    Report portal is an open source reporting and analysis framework. Starting from version 3.1.0 of the service-api XML parsing was introduced. Unfortunately the XML parser was not configured properly to prevent XML external entity (XXE) attacks. This allows a user to import a specifically-crafted XML file which imports external Document Type Definition (DTD) file with external entities for extraction of secrets from Report Portal service-api module or server-side request forgery. This will be resolved in the 5.4.0 release.

    Published: 23 Jun 2021
    —
    Unknown

    CVE-2021-3526

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 23 Jun 2021
    9.8
    Critical

    CVE-2020-20392

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php.

    Published: 23 Jun 2021
    5.4
    Medium

    CVE-2020-20391

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in GetSimpleCMS 3.4.0a in admin/snippets.php via (1) Add Snippet and (2) Save snippets.

    Published: 23 Jun 2021
    4.8
    Medium

    CVE-2020-20389

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in GetSimpleCMS 3.4.0a in admin/edit.php.

    Published: 23 Jun 2021
    6.1
    Medium

    CVE-2021-35438

    Last Modified: 13 Feb 2026

    phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator.

    Published: 23 Jun 2021
    —
    Unknown

    CVE-2021-25950

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 23 Jun 2021
    —
    Unknown

    CVE-2011-2926

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 23 Jun 2021
    —
    Unknown

    CVE-2011-1955

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 23 Jun 2021
    —
    Unknown

    CVE-2011-1942

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 23 Jun 2021
    —
    Unknown

    CVE-2011-1177

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 23 Jun 2021
    —
    Unknown

    CVE-2011-0023

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 23 Jun 2021
    4.8
    Medium

    CVE-2021-28977

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in GetSimpleCMS 3.3.16 in admin/upload.php by adding comments or jpg and other file header information to the content of xla, pages, and gzip files,

    Published: 23 Jun 2021
    7.2
    High

    CVE-2021-28976

    Last Modified: 21 Nov 2024

    Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.

    Published: 23 Jun 2021
    8.8
    High

    CVE-2021-31586

    Last Modified: 21 Nov 2024

    Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search.

    Published: 23 Jun 2021
    6.7
    Medium

    CVE-2021-31585

    Last Modified: 21 Nov 2024

    Accellion Kiteworks before 7.3.1 allows a user with Admin privileges to escalate their privileges by generating SSH passwords that allow local access.

    Published: 23 Jun 2021
    7.8
    High

    CVE-2021-21999

    Last Modified: 21 Nov 2024

    VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.10 and 4 prior to 2103) contain a local privilege escalation vulnerability. An attacker with normal access to a virtual machine may exploit this issue by placing a malicious file renamed as `openssl.cnf' in an unrestricted directory which would allow code to be executed with elevated privileges.

    Published: 23 Jun 2021
    9.8
    Critical

    CVE-2021-21998

    Last Modified: 21 Nov 2024

    VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A malicious actor with network access to the VMware Carbon Black App Control management server might be able to obtain administrative access to the product without the need to authenticate.

    Published: 23 Jun 2021
    7.5
    High

    CVE-2021-29084

    Last Modified: 14 Jan 2025

    Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 23 Jun 2021
    8.6
    High

    CVE-2021-29085

    Last Modified: 14 Jan 2025

    Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 23 Jun 2021
    7.5
    High

    CVE-2021-29087

    Last Modified: 14 Jan 2025

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to write arbitrary files via unspecified vectors.

    Published: 23 Jun 2021
    9.8
    Critical

    CVE-2021-27649

    Last Modified: 14 Jan 2025

    Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 23 Jun 2021
    5.3
    Medium

    CVE-2021-29086

    Last Modified: 14 Jan 2025

    Exposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 23 Jun 2021
    6.1
    Medium

    CVE-2021-35210

    Last Modified: 21 Nov 2024

    Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end.

    Published: 23 Jun 2021
    7.5
    High

    CVE-2022-27380

    Last Modified: 21 Nov 2024

    An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

    Published: 23 Jun 2021
    6.6
    Medium

    CVE-2021-3701

    Last Modified: 21 Nov 2024

    A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world R/W locations. This flaw allows an attacker to pre-create the directory, resulting in reading private information or forcing ansible-runner to write files as the legitimate user in a place they did not expect. The highest threat from this vulnerability is to confidentiality and integrity.

    Published: 23 Jun 2021
    7.8
    High

    CVE-2021-3600

    Last Modified: 21 Nov 2024

    It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code.

    Published: 23 Jun 2021
    1.9
    Low

    CVE-2021-34397

    Last Modified: 21 Nov 2024

    Bootloader contains a vulnerability in NVIDIA MB2, which may cause free-the-wrong-heap, which may lead to limited denial of service.

    Published: 22 Jun 2021
    3
    Low

    CVE-2021-34396

    Last Modified: 21 Nov 2024

    Bootloader contains a vulnerability in access permission settings where unauthorized software may be able to overwrite NVIDIA MB2 code, which would result in limited denial of service.

    Published: 22 Jun 2021
    3.9
    Low

    CVE-2021-34395

    Last Modified: 21 Nov 2024

    Trusty TLK contains a vulnerability in its access permission settings where it does not properly restrict access to a resource from a user with local privileges, which might lead to limited information disclosure, a low risk of modifcations to data, and limited denial of service.

    Published: 22 Jun 2021
    4.2
    Medium

    CVE-2021-34394

    Last Modified: 21 Nov 2024

    Trusty contains a vulnerability in the NVIDIA OTE protocol that is present in all TAs. An incorrect message stream deserialization allows an attacker to use the malicious CA that is run by the user to cause the buffer overflow, which may lead to information disclosure and data modification.

    Published: 22 Jun 2021
    4.2
    Medium

    CVE-2021-34393

    Last Modified: 21 Nov 2024

    Trusty contains a vulnerability in TSEC TA which deserializes the incoming messages even though the TSEC TA does not expose any command. This vulnerability might allow an attacker to exploit the deserializer to impact code execution, causing information disclosure.

    Published: 22 Jun 2021
    4.4
    Medium

    CVE-2021-34392

    Last Modified: 21 Nov 2024

    Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the tz_map_shared_mem function can bypass boundary checks, which might lead to denial of service.

    Published: 22 Jun 2021
    5.3
    Medium

    CVE-2021-34391

    Last Modified: 21 Nov 2024

    Trusty contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an integer overflow through a specific SMC call that is triggered by the user, which may lead to denial of service.

    Published: 22 Jun 2021
    5.3
    Medium

    CVE-2021-34390

    Last Modified: 21 Nov 2024

    Trusty contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an integer overflow through a specific SMC call that is triggered by the user, which may lead to denial of service.

    Published: 22 Jun 2021
    8.2
    High

    CVE-2021-34372

    Last Modified: 21 Nov 2024

    Trusty (the trusted OS produced by NVIDIA for Jetson devices) driver contains a vulnerability in the NVIDIA OTE protocol message parsing code where an integer overflow in a malloc() size calculation leads to a buffer overflow on the heap, which might result in information disclosure, escalation of privileges, and denial of service.

    Published: 22 Jun 2021
    7
    High

    CVE-2020-36394

    Last Modified: 21 Nov 2024

    pam_setquota.c in the pam_setquota module before 2020-05-29 for Linux-PAM allows local attackers to set their quota on an arbitrary filesystem, in certain situations where the attacker's home directory is a FUSE filesystem mounted under /home.

    Published: 22 Jun 2021
    7.5
    High

    CVE-2021-32701

    Last Modified: 21 Nov 2024

    ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. When you make a request to an endpoint that requires the scope `foo` using an access token granted with that `foo` scope, introspection will be valid and that token will be cached. The problem comes when a second requests to an endpoint that requires the scope `bar` is made before the cache has expired. Whether the token is granted or not to the `bar` scope, introspection will be valid. A patch will be released with `v0.38.12-beta.1`. Per default, caching is disabled for the `oauth2_introspection` authenticator. When caching is disabled, this vulnerability does not exist. The cache is checked in [`func (a *AuthenticatorOAuth2Introspection) Authenticate(...)`](https://github.com/ory/oathkeeper/blob/6a31df1c3779425e05db1c2a381166b087cb29a4/pipeline/authn/authenticator_oauth2_introspection.go#L152). From [`tokenFromCache()`](https://github.com/ory/oathkeeper/blob/6a31df1c3779425e05db1c2a381166b087cb29a4/pipeline/authn/authenticator_oauth2_introspection.go#L97) it seems that it only validates the token expiration date, but ignores whether the token has or not the proper scopes. The vulnerability was introduced in PR #424. During review, we failed to require appropriate test coverage by the submitter which is the primary reason that the vulnerability passed the review process.

    Published: 22 Jun 2021
    9.1
    Critical

    CVE-2021-32700

    Last Modified: 21 Nov 2024

    Ballerina is an open source programming language and platform for cloud application programmers. Ballerina versions 1.2.x and SL releases up to alpha 3 have a potential for a supply chain attack via MiTM against users. Http connections did not make use of TLS and certificate checking was ignored. The vulnerability allows an attacker to substitute or modify packages retrieved from BC thus allowing to inject malicious code into ballerina executables. This has been patched in Ballerina 1.2.14 and Ballerina SwanLake alpha4.

    Published: 22 Jun 2021
    6.5
    Medium

    CVE-2021-32699

    Last Modified: 21 Nov 2024

    Wings is the control plane software for the open source Pterodactyl game management system. All versions of Pterodactyl Wings prior to `1.4.4` are vulnerable to system resource exhaustion due to improper container process limits being defined. A malicious user can consume more resources than intended and cause downstream impacts to other clients on the same hardware, eventually causing the physical server to stop responding. Users should upgrade to `1.4.4` to mitigate the issue. There is no non-code based workaround for impacted versions of the software. Users running customized versions of this software can manually set a PID limit for containers created.

    Published: 22 Jun 2021
    4.9
    Medium

    CVE-2021-22383

    Last Modified: 21 Nov 2024

    There is an out-of-bounds read vulnerability in eCNS280_TD V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. The vulnerability is due to a message-handling function that contains an out-of-bounds read vulnerability. An attacker can exploit this vulnerability by sending a specific message to the target device, which could cause a Denial of Service (DoS).

    Published: 22 Jun 2021
    6.5
    Medium

    CVE-2021-22382

    Last Modified: 21 Nov 2024

    Huawei LTE USB Dongle products have an improper permission assignment vulnerability. An attacker can locally access and log in to a PC to induce a user to install a specially crafted application. After successfully exploiting this vulnerability, the attacker can perform unauthenticated operations. Affected product versions include:E3372 E3372h-153TCPU-V200R002B333D01SP00C00.

    Published: 22 Jun 2021
    7.5
    High

    CVE-2021-22363

    Last Modified: 21 Nov 2024

    There is a resource management error vulnerability in eCNS280_TD V100R005C10SPC650. An attacker needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper resource management of the function, the vulnerability can be exploited to cause service abnormal on affected devices.

    Published: 22 Jun 2021
    4.9
    Medium

    CVE-2021-22342

    Last Modified: 21 Nov 2024

    There is an information leak vulnerability in Huawei products. A module does not deal with specific input sufficiently. High privilege attackers can exploit this vulnerability by performing some operations. This can lead to information leak. Affected product versions include: IPS Module versions V500R005C00, V500R005C10, V500R005C20; NGFW Module versions V500R005C00,V500R005C10, V500R005C20; SeMG9811 versions V500R005C00; USG9500 versions V500R001C00, V500R001C20, V500R001C30, V500R001C50, V500R001C60, V500R001C80, V500R005C00, V500R005C10, V500R005C20.

    Published: 22 Jun 2021
    5.3
    Medium

    CVE-2021-22378

    Last Modified: 21 Nov 2024

    There is a race condition vulnerability in eCNS280_TD V100R005C00 and V100R005C10. There is a timing window exists in which the database can be operated by another thread that is operating concurrently. Successful exploit may cause the affected device abnormal.

    Published: 22 Jun 2021
    7.2
    High

    CVE-2021-22377

    Last Modified: 21 Nov 2024

    There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S5700 V200R019C00SPC500, S6700 V200R019C00SPC500 and S7700 V200R019C00SPC500. A module does not verify specific input sufficiently. Attackers can exploit this vulnerability by sending malicious parameters to inject command. This can compromise normal service.

    Published: 22 Jun 2021
    5.5
    Medium

    CVE-2021-22366

    Last Modified: 21 Nov 2024

    There is an out-of-bounds read vulnerability in eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. The vulnerability is due to a function that handles an internal message contains an out-of-bounds read vulnerability. An attacker could crafted messages between system process, successful exploit could cause Denial of Service (DoS).

    Published: 22 Jun 2021
    3.3
    Low

    CVE-2021-22365

    Last Modified: 21 Nov 2024

    There is an out of bounds read vulnerability in eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. A local attacker can exploit this vulnerability by sending specific message to the target device. Due to insufficient validation of internal message, successful exploit may cause the process and the service abnormal.

    Published: 22 Jun 2021
    6.4
    Medium

    CVE-2021-32644

    Last Modified: 21 Nov 2024

    Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. The attack requires user authentication to access the random.php page unless the site is running in demo mode. This issue has been resolved in 4.4.3.

    Published: 22 Jun 2021
    7.8
    High

    CVE-2021-22361

    Last Modified: 21 Nov 2024

    There is an improper authorization vulnerability in eCNS280 V100R005C00, V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SPC200. A file access is not authorized correctly. Attacker with low access may launch privilege escalation in a specific scenario. This may compromise the normal service.

    Published: 22 Jun 2021